Teams should prioritise ISO 27001:2022 when they are still early in implementation and have enough time to absorb the updated structure before their certification deadline. If certification is urgent or already well underway on 2013, finishing that path first can be more efficient, provided the organisation still plans a timely move before the 2025 transition cutoff.
Why the timing decision depends on implementation stage, not just the standard version
The practical question is not which version is “better” in the abstract, but which path reduces delivery risk without creating avoidable rework. If an organisation is still early, moving to ISO/IEC 27001:2022 Information Security Management can save effort by aligning the ISMS to the current structure once, rather than building controls against the older version and then remapping them later.
If certification is already close, the decision is more about execution efficiency than technical purity. Completing the 2013 effort can be sensible when the team has already invested in evidence, internal audit, and stage-readiness, provided the organisation does not lose sight of the transition deadline and the follow-on work is scheduled rather than deferred indefinitely.
What changes in 2022 that affects the certification path
iso 27001:2022 is not a different security philosophy, but it does reflect a cleaner control structure and updated control set. That matters because the standard now better aligns with current implementation patterns such as cloud security, access governance, and modern authentication expectations, which can reduce interpretation friction during design and audit.
For teams still designing policies, statements of applicability, or control ownership, the newer version avoids the common mistake of building around controls that are already being retired from practical use. For teams that have already stabilised a 2013-based programme, the gain from switching immediately is smaller, because most of the underlying management system work still transfers.
That is why the strongest decision signal is the amount of untouched implementation work remaining. If the organisation still needs to define controls, map evidence, and normalise ownership, the 2022 version is usually the more efficient destination. If the programme is mostly complete and the remaining work is certification administration, finishing the current path first may be the lower-friction choice.
How to choose the cheaper path without creating transition debt
The key trade-off is between near-term certification speed and medium-term rework. Choosing 2013 late in the cycle can be efficient, but only if the organisation treats the later transition as a real programme item with ownership, timeline, and budget. Otherwise, the company risks passing one audit and then rediscovering the same mapping and evidence work during transition.
When the 2022 path is preferred, the rationale is usually consolidation: one control model, one evidence structure, and one set of internal ownership decisions that can carry forward. That is especially useful where the organisation runs multiple environments, uses shared tooling, or has frequent control changes that would make a second mapping exercise expensive.
When the 2013 path is preferred, the rationale is usually schedule protection. If the organisation has already committed to audit dates, supplier dependencies, or regulatory deadlines, the immediate objective may be to complete the current certification and then manage the version change as a controlled follow-on project.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | Version choice affects how access controls are structured and evidenced in the ISMS. |
| A.5.23 — Information security for use of cloud services | 2022 updates reflect modern cloud control expectations that can influence implementation effort. | |
| A.8.5 — Secure authentication | Authentication control changes can affect remapping effort between 2013 and 2022. | |
| Recommendation — Align the control set to the current standard so access control evidence maps cleanly during certification. Update cloud security control mapping before certification if cloud use is materially in scope. Revalidate authentication controls against the current annex before locking the certification path. | ||
Practitioner Guidance
What to prioritise: Compare the remaining work, not the number of days left on the calendar. If the programme still needs major control design or policy rework, move to 2022; if it is already audit-ready, protect the current certification path and plan the transition immediately after.
What to verify: Confirm that the transition plan has an owner, a date, and a funded implementation window. A decision to finish 2013 is only low-risk when the organisation can show the 2022 move will happen on a defined schedule rather than as an open-ended intent.
Practitioner takeaway: The right choice is whichever path avoids duplicate work while still leaving enough time to complete the required transition cleanly before the cutoff.
Related resources from NHI Mgmt Group
- How should organisations prepare for ISO 27001:2022 certification if they rely on cloud access and admin credentials?
- When should organisations prioritise an ISO 27001 consultant over an internal compliance lead?
- When should organisations prioritise SOC 2 over ISO 27001?
- How should security teams govern non-human identities for ISO 27001?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org